Cybersecurity · Identity

Identity and Access Management

Most intrusions we are called into did not begin with malware. They began with a working username and password. Once cloud email, file storage, accounting platforms and remote access all authenticate against the same directory, that directory becomes the thing worth protecting.

Identity and access management is the practice of deciding who can reach what, under which conditions, and proving that the decision is still correct months later.

The problem

Why access quietly drifts out of control

Access accumulates. Someone changes roles and keeps both sets of permissions. A contractor is added to a shared mailbox for one project and stays there for three years. A departed employee's account is disabled in one system and forgotten in four others. None of this is negligence; it is what happens when access is granted by request and never reviewed.

Meanwhile the authentication itself is often weaker than people assume. Multi-factor authentication may be enabled for staff but skipped for the administrator account, or enforced on email but not on the remote desktop gateway that faces the internet. Attackers look for exactly those exceptions.

The result is an environment where a single reused password can reach payroll data, and where nobody can answer the basic audit question: who currently has access to this, and why?

What we do

How Griffin IT Group delivers it

We start with a full inventory of accounts and sign-in paths, then close the gaps in an order that does not interrupt the working day.

  1. 01

    Enforce strong authentication everywhere

    Multi-factor authentication applied to every account — including administrators, service mailboxes and remote access — using app-based approval or passkeys rather than SMS wherever the platform allows it.

  2. 02

    Design Conditional Access properly

    Policies that assess who is signing in, the device they are using, its compliance state and the sensitivity of what they are reaching. Legacy authentication protocols that bypass MFA entirely are blocked and monitored.

  3. 03

    Separate privileged access

    Administrative rights are removed from day-to-day accounts and issued through named admin identities with stronger controls, so a phished mailbox does not become a tenant-wide compromise.

  4. 04

    Make roles the unit of access

    Permissions are attached to role-based groups rather than individuals. Onboarding becomes 'add to the accounting role' instead of copying whatever the last hire happened to have.

  5. 05

    Close the leaver gap

    A documented offboarding runbook covering directory accounts, mail forwarding, mobile devices, SaaS platforms, VPN, shared credentials and any customer-facing accounts, executed the same day.

  6. 06

    Review and report

    Periodic access reviews with the department owner, plus reporting on privileged accounts, stale accounts and MFA coverage — the evidence insurers and auditors now ask for.

Security considerations

What to plan for before you switch policies on

Identity changes are felt immediately by every user, so sequencing matters. We pilot with a small group, keep emergency break-glass accounts documented and excluded, and stage enforcement so that shared devices, scanners, older line-of-business applications and mobile mail clients are handled before a policy becomes mandatory.

We also plan for the recovery case: what happens when a phone is lost, when someone is travelling, or when the person who approves access is away. Controls that leave no safe path are the controls that get switched off in a hurry.

  • Pilot groups before enforcement
  • Documented break-glass accounts
  • Legacy app compatibility review
  • Shared and kiosk device handling
  • Self-service reset with verification
  • Written escalation path

Business outcome

What changes for the organization

  • Stolen passwords stop being enough
  • Faster, cleaner staff onboarding
  • Same-day, complete offboarding
  • Answerable access questions
  • Insurance and audit evidence
  • Fewer standing administrator rights

Where this fits

This work is delivered as part of the wider security programme described on cybersecurity services for St. Catharines organizations.

Questions

Frequently asked questions

Will multi-factor authentication slow our staff down?
In practice most people approve a prompt a few times a week. Sign-ins from a known, compliant device on a normal pattern can be trusted for a period, so the prompts concentrate where the risk actually is — new devices, unusual locations and administrative access.
We have Microsoft 365 Business Premium. Do we need extra products?
Usually not for identity. Business Premium includes Entra ID Plan 1, which covers Conditional Access, self-service password reset and the reporting most small and mid-sized organizations need. The work is configuration and review, not additional licensing.
Can you control access to platforms that are not Microsoft?
Yes, where the platform supports single sign-on or SAML we connect it to the same directory so access and offboarding are centralized. Where it does not, we document the account, assign an owner and include it in the offboarding runbook.

Next step

Talk to Griffin IT Group about your St. Catharines IT environment

Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.